Offensive security boutique · Brazil · Europe · US

Real offensive pentesting. Senior experts, AI, and our own methodology.

We test web applications, APIs and AI/LLM systems the way a real attacker would — and deliver a report your board understands and your team can act on.

Reply within 24h Retest included NDA before scoping
final-report.pdf · Finding PM-2026-014 CRITICAL · CVSS 9.8

Indirect prompt injection via RAG → customer data exfiltration

POST /api/v2/assistant/chat
{"message": "Summarize the attached document"}
agent invokes tool export_customers()12,480 records returned to an anonymous user
Impact
LGPD / GDPR
PoC
Reproducible
Retest
Fixed ✓
12+years in offensive security
400+pentests delivered
1.900+critical findings reported
92client satisfaction
Industries served Fintechs and digital banksHealthtechB2B SaaSE-commerce and retailAI platforms

Services

Four attack surfaces. One standard: find what automated tools don't.

Every engagement is manual, led by a senior expert and accelerated by AI and in-house tooling.

Web App Pentest

Authentication, authorization, business logic, injections, SSRF, XSS, race conditions. Black, grey and white-box.

OWASP WSTGASVS L2
Typical timeline: 5–15 dias

API Pentest

REST, GraphQL, gRPC and webhooks. BOLA/IDOR, mass assignment, rate limiting, JWT/OAuth, logic abuse.

OWASP API Top 10OpenAPI-driven
Typical timeline: 5–10 dias

Cloud & External Infra

Exposed surface, AWS/Azure/GCP configuration, Kubernetes, leaked secrets, escalation paths.

PTESCIS Benchmarks
Typical timeline: 5–10 dias

AI / LLM Pentest

Your chatbot, copilot or agent is already in production. Has anyone tried to break it?

AI systems create a new attack surface: natural language becomes an attack vector and every tool connected to the model becomes a path to data and actions. We test the whole system — model, prompts, RAG, tools, agents and integrations — with a reproducible PoC for every finding.

Test my AI system
  • Direct and indirect prompt injectionThrough users, documents, emails, web pages and tool results.
  • Data and system prompt leakageExtraction of secrets, PII and cross-tenant RAG context.
  • Tool and agent abuseUnauthorized actions, escalation via function calling, agent-driven SSRF.
  • Jailbreaks and guardrail bypassProhibited content, fraud, manipulation of automated decisions.
  • RAG poisoning and supply chainPoisoning of knowledge bases, models and third-party dependencies.
  • Model DoS and cost abuseToken exhaustion, agent loops, denial of wallet.

Why Pentest Machine

Senior humans. AI working for them. Never the other way around.

01

Certified experts

Every test is run by professionals holding OSCP, OSWE, OSEP, CRTO e BSCP with a track record in bug bounty and published CVEs.

02

AI + in-house tooling

AI agents and internal tooling widen recon and triage coverage, freeing the expert for what needs creativity: logic, chaining and exploitation.

03

A report that drives action

Executive summary for the board, technical detail with PoC for the team, a prioritized remediation plan and a retest included in the price.

Methodology

Six steps, zero surprises.

01

Scope & NDA

Rules of engagement, testing windows, emergency contacts.

02

Recon

Surface mapping with AI and in-house tooling.

03

Exploitation

Manual, creative, chained. Critical alerts within 24h.

04

Post-exploitation

Real business impact, not just CVSS.

05

Report

Executive + technical, PoC and remediation plan.

06

Retest

Fix validation and final attestation.

Aligned with OWASP WSTGOWASP ASVSOWASP LLM Top 10PTESNIST SP 800-115ISO 27001PCI-DSSBACENLGPDGDPRSOC 2
In three days the team chained an authorization flaw in the API with a prompt injection in our assistant and reached customer data. The report was straight to the point, the board understood the risk on first read, and the retest confirmed the fixes before our PCI audit.
Rafael M.CISO, central-bank-regulated fintech

Frequently asked questions

What everyone asks before hiring a pentest.

How much does a pentest cost?

It depends on scope: number of applications, endpoints, authenticated functionality and whether AI systems are involved. A mid-size web application pentest usually takes 5 to 15 working days. We send a fixed-price proposal within 24h of understanding the scope.

What is the difference between a vulnerability scan and a pentest?

A scanner automates the search for known patterns and produces false positives. A pentest is run by an expert who exploits logic flaws, chains vulnerabilities and proves real impact with a PoC — which PCI-DSS, SOC 2 and ISO 27001 audits expect.

What is an AI / LLM pentest?

Security testing of chatbots, copilots and agents: direct and indirect prompt injection, data leakage via RAG, tool and agent abuse, jailbreaks and model DoS, following the OWASP Top 10 for LLM and MITRE ATLAS. We test the whole system, not just the model.

Is the retest included?

Yes. Once your team fixes the findings, we validate the fixes and issue a final attestation — at no extra cost, within 90 days of report delivery.

Do you sign NDAs and work outside the US?

Yes. We sign an NDA before any scope detail, work in English, Portuguese and Spanish, and invoice in the US, the EU or Brazil.

Blog

Latest articles

From the blog: offensive security in practice.

See all articles

Request a quote

Get a proposal within 24h.

Tell us what you need tested. An expert — not a salesperson — replies with scope, timeline and price.

  • NDA available before any detail is shared
  • Support in EN, PT and ES
  • Invoicing in the US, EU or Brazil